Customer Case Study Patch, Monitor, and Manage Servers Don Platt Manager, Technical Services Infrastructure Architect Server Management Suite 1
Agenda Introduction What Altiris products we have and use What specifically is used in direct support of written policies, procedures, and configuration standards Explain how Altiris is used to ensure compliance Other unique use cases vital to IT and Business Operations i.e. Monitor Solution, Workflow, Task Server, ADMT Server Management Suite 2
Introduction About Gentiva Home Health and Hospice 60,000+ employees 600+ locations 1,200+ servers 5 AD Domains 98% Virtualized Been working with Altiris products since 1999 Lead the Midrange Systems Management team Server Management Suite 3
What we have licensed and what we use Server Management Suite Patch Management Monitor Solution Software Delivery Inventory Solution Task Server Workflow Asset Management Suite Location Management Contract Management Server Management Suite 4
Policies, procedures, and Configuration Standards Backup Policy Patch Policy Anti-malware Policy Windows Server Configuration Standards and Guidelines DR Policy Server Management Suite 5
Backup Policy All servers will be backed up Exceptions are allowed Ok, how do we ensure this policy is 100% consistently adhered to? The challenge/the Gap How does Altiris fill this gap? Software Delivery Inventory Solution Monitoring Policy Custom Inventory Server Management Suite 6
Server Management Suite 7
Patch Policy We will patch the following vendor s software if found on our servers Filters (FKA Collections) Pre-Prod Prod DCs-1 DCs-2 Manually Patched Wednesday after Patch Tuesday Altiris creates a ticket, assigned to my team contains a link to Software Bulletins revised in the past 35 days. Review and communicate No objections, approve Exceptions Filters are created on a per bulletin basis Compliance reports Patch Agent is aware of other activities Server Management Suite 8
Sample Month Week 1 Sunday Monday Tuesday Wednesday Thursday Friday Saturday Report on Prod deployment & remediate Report on Prod deployment & remediate Report on Prod deployment & remediate Report on Prod deployment & remediate Report on Prod deployment & remediate Report on Prod deployment & remediate Week 2 MS Releases Patches Ticket Created/Review Board will review for applicability Review Board will review for applicability Week 3 Update ticket with industry feedback and begin Pre-Prod and DCs Pre-Prod and DC patches are installed Report on Pre-Prod and DC deployment & remediate Report on Pre-Prod and DC deployment & remediate Report on Pre-Prod and DC deployment & remediate Report on Pre-Prod and DC deployment & remediate Week 4 App Owners to test functionality on Pre-Prod App Owners to test functionality on Pre-Prod App Owners to test functionality on Pre-Prod App Owners to test functionality on Pre-Prod App Owners to test functionality on Pre-Prod Production patches are installed Server Management Suite 9
Server Management Suite 10
Server Management Suite 11
Anti-Malware Policy Anti-malware software is to be installed, running and virus definitions are up to date Software Delivery Inventory Solution Monitor Solution Anti-Malware definition files are monitored to ensure they are recent. Anti-Malware services must be installed and running Specific Anti-Malware services (e.g. Mail Security components for Exchange Servers) are installed and running. Server Management Suite 12
Server Management Suite 13
Windows Server Configuration Standards and Guidelines Renaming of local administrator For domain joined servers, a GPO is in place that renames the local administrator account. For DMZ servers not joined to the domain, there is a Configuration Policy in Altiris SMS that ensures the local administrator account has been changed. NTP For domain joined servers, they automatically synchronize their clocks with the PDC Emulator. For DMZ servers not joined to the domain, there is a Configuration Policy in Altiris SMS that configures NTP to synchronize with the internal PDC Emulator. Server Management Suite 14
Windows Server Configuration Standards and Guidelines Ensuring non-dmz servers are (and remain) joined to the domain There is a Notification Policy in Altiris SMS that will alert us to any Server OS found on the network, not joined to the Domain. Server Provisioning Clone via vcenter But from there, all activities are through Altiris Provisioning OU Downtime for Monitoring Patch Policies Core software I.E. anti-malware, backup agents Daily report on servers in this OU/Filter TSM Registration Server Management Suite 15
Server Management Suite 16
Disaster Recovery Maintain a Filter of all Tier 1 Servers Report to display key specs Automatic notification when New physical servers are added Aggregate vspecs pass a certain threshold Server Management Suite 17
Other unique use cases vital to IT and Business Operations Workflow Special Backups Task Server IIS Log Cleanups IIS App Pool Warm-up Plumtree Fix Lots-O AD Jobs ADMT Server Management Suite 18
Server Management Suite 19
Other unique use cases vital to IT and Business Operations Automation Policies Monitor the aforementioned jobs Patch Management notifications Monitor Solution N+1 Stats in VMware Auto-remediation Historical Cacti-like reporting RightFax Automatic Event Correlation Web Services to open tickets in our SD Bidirectional Communication Server Management Suite 20
Server Management Suite 21
Server Management Suite 22
Server Management Suite 23
Questions Any Questions? Server Management Suite 24
Thank you! Don Platt Don.Platt@Gentiva.com Copyright 2013 Symantec Corporation. All rights reserved. Symantec and the Symantec Logo are trademarks or registered trademarks of Symantec Corporation or its affiliates in the U.S. and other countries. Other names may be trademarks of their respective owners. This document is provided for informational purposes only and is not intended as advertising. All warranties relating to the information in this document, either express or implied, are disclaimed to the maximum extent allowed by law. The information in this document is subject to change without notice. Server Management Suite 25